PLUGIN SECURITY
Is Visual CSS Style Editor safe?
Style your WordPress site visually. Discover the most popular front-end design plugin! Try live demo.
What this plugin does
- Slug:
yellow-pencil-visual-theme-customizer - Author: YellowPencil
- 30000+ active installs
- 82/100 rating (90 reviews on wordpress.org)
- 1504408 all-time downloads
- On WordPress.org since 2015-08-21
csscss editorcustomizedesignvisual css
Maintenance status
- Latest known version: 7.6.7
- Last updated: 2026-08-23 1:40pm GMT
- Tested up to WordPress: 7.1
Known vulnerabilities
5 known CVEs on file for Visual CSS Style Editor. Reported between 2019 and 2024.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-47348 | Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 7.6.5 | 7.6.5 | 2024-09-30 | ✓ fixed in latest |
| CVE-2024-43963 | Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.6.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 7.6.4 | 7.6.4 | 2024-08-26 | ✓ fixed in latest |
| CVE-2022-33961 | Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.5.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.0 | < 7.5.9 | 7.5.9 | 2023-04-18 | ✓ fixed in latest |
| CVE-2021-24934 | Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.5.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 7.5.4 | 7.5.4 | 2022-01-03 | ✓ fixed in latest |
| — | Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.2.1 | — | Unknown | < 7.2.1 | 7.2.1 | 2019-04-12 | ✓ fixed in latest |
| CVE-2019-11886 | Visual CSS Style Editor [yellow-pencil-visual-theme-customizer] < 7.2.1 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 7.2.1 | 7.2.1 | 2019-04-11 | ✓ fixed in latest |
How to fix it
Keep Visual CSS Style Editor updated — 7.6.7 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager — 3000000+ active installs — 98/100 (1869) — max PHP 8.4
- Code Snippets — 1000000+ active installs — 94/100 (509) — max PHP 8.4
- Simple Custom CSS Plugin — 100000+ active installs — 94/100 (159)
- SiteOrigin CSS — 100000+ active installs — 98/100 (153)
- Blocks Animation: CSS Animations for Gutenberg Blocks — 90000+ active installs — 94/100 (69) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.